Remote Access Vulnerability in DCIM dcTrack from Panduit
CVE-2025-66238

7.4HIGH

Key Information:

Vendor

Sunbird

Vendor
CVE Published:
4 December 2025

What is CVE-2025-66238?

The dcTrack systems developed by Panduit contain a security issue that could allow an authenticated user to exploit remote access functionalities. By leveraging these features, an attacker could redirect network traffic, potentially gaining access to restricted services or sensitive data on the host system. This situation underscores the need for enhanced security protocols and monitoring to prevent unauthorized access and protect critical information.

Affected Version(s)

DCIM dcTrack 0

IQ 0

DCIM dcTrack 9.2.3

References

CVSS V4

Score:
7.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

notnotnotveg ([email protected]) reported these vulnerabilities to CISA.
.
CVE-2025-66238 : Remote Access Vulnerability in DCIM dcTrack from Panduit